5.5
CVE-2022-22899
- EPSS 0.86%
- Veröffentlicht 17.02.2022 13:15:07
- Zuletzt bearbeitet 09.07.2026 01:17:13
- CVE-Watchlists
- Unerledigt
Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.86% | 0.543 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| NIST | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:N/I:N/A:P
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
http://coreftp.com/forums/viewtopic.php?f=15&t=4022509
https://yoursecuritybores.me/coreftp-vulnerabilities/